MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f1e420fee19df82b35d05e445eaeab7cb1e8998665794898e3c0049b7cfde7aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Threat unknown
Vendor detections: 4
| SHA256 hash: | f1e420fee19df82b35d05e445eaeab7cb1e8998665794898e3c0049b7cfde7aa |
|---|---|
| SHA3-384 hash: | fd0b8ea612ece442a750c22ecd6763f99e0dfa7060d00145eb5fd7db9ff0c2f2b434d72ab91eb916cfc48be930c97bc8 |
| SHA1 hash: | 1578cfef86c5ad6eedd87f65ae598026c16acd7e |
| MD5 hash: | 7ccbf4dccac4bb7e5cd7b9c3b6513c75 |
| humanhash: | indigo-table-mike-kentucky |
| File name: | gpon |
| Download: | download sample |
| File size: | 788 bytes |
| First seen: | 2026-08-02 23:13:03 UTC |
| Last seen: | 2026-08-03 08:43:51 UTC |
| File type: | sh |
| MIME type: | text/x-shellscript |
| ssdeep | 12:8e9LxyxA2XdG06P91KQ1KN51KUFFtTHXYX6QyTkyMxS:8e9FyK2Ul9TqDFDTHydyTIg |
| TLSH | T16B019CCDDCD54170FA488A2A75BA6691E34D694F48C82E0DB01EDBA0DF4C961B21B737 |
| TrID | 70.0% (.SH) Linux/UNIX shell script (7000/1) 30.0% (.) Unix-like shebang (var.3) (gen) (3000/1) |
| Magika | shell |
| Reporter | |
| Tags: | sh |
Intelligence
File Origin
# of uploads :
3
# of downloads :
60
Origin country :
DEVendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
Score:
30%
Verdict:
Benign
File Type:
SCRIPT
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Malware family:
Mirai
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.06
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
sh f1e420fee19df82b35d05e445eaeab7cb1e8998665794898e3c0049b7cfde7aa
(this sample)
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.